The Defense Manpower Data Center (DMDC), the Pentagon's personnel-data agency, is sending breach notices to current and former military members, civilian staff and others. The notices say unauthorized users had access to unencrypted personal records for about nine months, from October 2025 until 16 July 2026. Defense officials have given CNN, MeriTalk and Federal News Network a count of 2.76 million living individuals and 294,000 deceased individuals, about 3.05 million records in total. Published figures vary. TechRadar's headline says 2.7 million. BleepingComputer and TechCrunch say "nearly" or "about" 2.8 million living people. Military Times cites two unnamed people who say about four million may be affected. The notification letter itself gives no count. Only the Department of Defense (which now also calls itself the Department of War) has confirmed the breach. The attacker has not been identified, and no group has claimed responsibility.
What Happened
Military Times and SecurityWeek report that the notification letter is dated 18 September 2026. Recipients have posted copies on Reddit, and Military Times says two defense officials confirmed the letter is authentic. Its main points:
- Discovery: "On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files."
- Remediation: DMDC says it "immediately updated the file sharing system to patch the vulnerability and the system was restored."
- Dwell time: "Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII."
- Misuse: The department says it has "no indications of misuse of the accessed information." A DoD spokesperson repeated this to MeriTalk.
About two months passed between discovery in mid-July and the 18 September letter. IDX (Identity Theft Guard Solutions), which DoD contracts for this work, is mailing the notices. Reporting differs slightly on what was breached. BleepingComputer's headline calls it the Pentagon's "human resources management system." The letter and most other outlets describe a file server reached through a file-sharing system. The letter's own wording is more specific and should be preferred.
What Was Taken
The letter says the exposed data "varied by individual." Each recipient's Social Security number was exposed together with at least one more identifier from this list:
- Full name
- Date of birth
- Contact information
- Sex and race
- Military personnel information, including military occupational specialty (MOS)
The scale of the data store matters too. DMDC holds more than 60 million records (FY2024) covering service members, civilians, contractors, family members, retirees and veterans. TechCrunch notes that DMDC also calls itself the military's "leading identity management provider." It links people to the credentials, such as CAC smart cards, that grant access to Pentagon systems, buildings and bases. Based on the notices, the exposed data was personnel records, not credentials. The affected group also includes about 294,000 deceased people, whose identities are often used in benefits and identity fraud because nobody is watching their credit.
Why It Matters
- Targeting value: If an attacker holds an SSN together with MOS data, they can identify people in sensitive specialties such as intelligence, special operations, cyber and nuclear roles. That supports spear-phishing, social engineering and recruitment approaches. CNN framed the story mainly as a national security concern.
- Undetected for nine months: The access was not caught by monitoring. It was found only when someone discovered the vulnerability. Long dwell time on an internet-facing file transfer system fits the pattern of earlier mass-exploitation campaigns against managed file transfer (MFT) products.
- Unencrypted data at rest: The letter states the PII was unencrypted. Nine months of access to plaintext SSNs is a basic control failure at an agency whose website says "security of identity information is paramount."
- Part of a pattern: TechCrunch places this in "a spate of thefts involving federal workers' data in recent months." The incident adds to a growing body of US government personnel data available to adversaries.
- Attribution unknown: No actor has been named and no group has claimed it. Months of quiet access with no extortion activity reported so far is more consistent with espionage than with a ransomware-style operation. That is analytical inference and has not been confirmed.
The Attack Technique
Public detail is limited. What is known:
- Initial access: A vulnerability in an unnamed DMDC file-sharing system. The letter does not name the product or describe the flaw, and SecurityWeek and TechCrunch both point out that it is unspecified.
- Actors: A "small number of unauthorized users," with no further detail.
- Access: File-level access to a server holding unencrypted PII, which the attackers kept from October 2025 to 16 July 2026.
- Response: The system was patched and restored. DMDC began incident response under OMB and DoD guidance and says it is "assess[ing] and enhanc[ing]" the system's security posture.
It is still unknown whether the flaw was a zero-day or a known CVE that went unpatched, which product was affected, and whether anything beyond file reads happened, such as lateral movement or persistence. Defenders should treat any reported link to a specific MFT product as speculation until DoD or a vendor advisory confirms it.
What Organizations Should Do
- Inventory and harden file-sharing and MFT systems. List every internet-facing file transfer and file-sharing appliance. Apply vendor patches quickly, and put administrative and upload interfaces behind VPN or zero-trust access where you can.
- Encrypt sensitive PII at rest and limit how long staging copies live. File shares should not hold plaintext SSN datasets. Use application- or file-level encryption, tokenize SSNs where possible, and delete bulk exports once the transfer is complete.
- Hunt for long-dwell access. Review at least 12 months of file-server and MFT logs for unusual source IPs, off-hours bulk downloads, new or dormant accounts, and web shells. This incident went unnoticed for about nine months.
- Monitor data egress. Set baselines for normal transfer volumes from systems that hold PII and alert on deviations. Feed MFT logs into the SIEM instead of leaving them on the appliance.
- Brief exposed staff on targeted social engineering. Defense contractors and agencies whose staff overlap with DMDC records should warn people about phishing, vishing and fake recruitment approaches that use personnel details. Affected individuals should enroll in the IDX monitoring on offer. BleepingComputer reports 12 months of coverage with an enrollment deadline of 19 August 2027. They should also consider a credit freeze.
- Protect records of deceased individuals. Organizations with deceased-person records in scope should check that death notifications have reached the credit bureaus and the SSA, so the identities are harder to reuse.
Sources: Massive Pentagon hack sees records of 2.7 million US military perso... | Hackers stole Pentagon personnel records of over 3 million people | Hackers stole millions of US military personnel records during mont... | Pentagon Personnel Agency Data Breach Impacts 3 Million ... | Three Million Affected in Pentagon Personnel Agency Data Breach - S... | Pentagon data breach of military personnel raises national security... | Military personnel data exposed in breach, agency warns | Pentagon Database Breach Exposes Personal Information of More Than...